Moderate severity vulnerability that affects org.springframework:spring-core
Moderate severity
GitHub Reviewed
Published
Oct 17, 2018
to the GitHub Advisory Database
•
Updated Mar 5, 2024
Package
Affected versions
>= 4.1.0, < 4.1.5
Patched versions
4.1.5
Description
Published by the National Vulnerability Database
Mar 10, 2015
Published to the GitHub Advisory Database
Oct 17, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 5, 2024
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
References